this post was submitted on 31 Mar 2025
210 points (98.2% liked)

Selfhosted

46595 readers
1570 users here now

A place to share alternatives to popular online services that can be self-hosted without giving up privacy or locking you into a service you don't control.

Rules:

  1. Be civil: we're here to support and learn from one another. Insults won't be tolerated. Flame wars are frowned upon.

  2. No spam posting.

  3. Posts have to be centered around self-hosting. There are other communities for discussing hardware or home computing. If it's not obvious why your post topic revolves around selfhosting, please include details to make it clear.

  4. Don't duplicate the full text of your blog or github here. Just post the link for folks to click.

  5. Submission headline should match the article title (don’t cherry-pick information from the title to fit your agenda).

  6. No trolling.

Resources:

Any issues on the community? Report it using the report flag.

Questions? DM the mods!

founded 2 years ago
MODERATORS
 

I already host multiple services via caddy as my reverse proxy. Jellyfin, I am worried about authentication. How do you secure it?

you are viewing a single comment's thread
view the rest of the comments
[–] softcat@lemmy.ca -3 points 1 month ago (4 children)

CloudFlare tunnel with Zero Trust, plus their bot and abuse blocking. Users can get in with the right oauth, plus only allowed from the countries I know they're in. Then just their username and password on jellyfin.

[–] Dhs92@programming.dev 9 points 1 month ago (3 children)

Doesn't streaming media over a cloudflare tunnel/proxy violate their ToS

[–] softcat@lemmy.ca 1 points 1 month ago* (last edited 1 month ago) (1 children)

They prohibit large amounts of media being streamed, and they reserve the right to suspend or terminate accounts for it. Multiple years in, that has not happened.

Edit: here, you can read https://blog.cloudflare.com/updated-tos/

[–] merthyr1831@lemmy.ml 3 points 1 month ago

Cloudflare is known for being unreliable with how and when it enforces the ToS (especially for paying customers!). Just because they haven't cracked down on everyone doesn't mean they won't arbitrarily pick out your account from thousands of others just to slap a ban on. There's inherent risk to it

[–] Dave@lemmy.nz 0 points 1 month ago

No, they removed that clause some 2 or 3 years back.

[–] ftbd 5 points 1 month ago (1 children)

I hate the cloudflare stuff making me do captchas or outright denying me with a burning passion. My fault for committing the heinous crime of using a VPN!

[–] softcat@lemmy.ca -2 points 1 month ago
[–] rice@lemmy.org 1 points 1 month ago (1 children)

just run wireguard on the jelly server..

[–] softcat@lemmy.ca 1 points 1 month ago (1 children)

My users aren't going to figure that out.

[–] rice@lemmy.org 0 points 1 month ago (1 children)

they don't have to figure it out, you are the one running it

[–] softcat@lemmy.ca 1 points 1 month ago

They'd have to connect to it, and possibly reconnect. That aspect is the issue.

[–] Netrunner@programming.dev 1 points 1 month ago* (last edited 1 month ago) (1 children)

Using cloudflare tunnels means nothing is encrypted and cloudflare sees all.

[–] softcat@lemmy.ca 0 points 1 month ago

Oh no they'll see I'm watching TNG